|
php.net | support | documentation | report a bug | advanced search | search howto | statistics | random bug | login |
[2003-04-19 06:03 UTC] adrian at planetcoding dot net
The safe_mode seems to be too strict when using show_source: PHP can delete a uploaded file which is owned by the webserver, kan read it w/ fopen or readfile, can do anything with it except of show_source. I just get the safe_mode restriction in effect... - message. If I use fopen and highlight_string, it works fine. ./configure: './configure' '--prefix=/usr/share' '--bindir=/usr/bin' '--libdir=/usr/lib' '--datadir=/usr/share/php' '--includedir=/usr/include' '--with-apxs=/usr/sbin/apxs' '--enable-force-cgi-redirect' '--with-config-file-path=/etc' '--with-openssl' '--with-zlib' '--enable-bcmath' '--with-bz2' '--enable-calendar' '--with-curl' '--enable-exif' '--enable-ftp' '--with-gd' '--enable-gd-native-ttf' '--enable-gd-imgstrttf' '--with-gettext' '--with-iconv' '--enable-mbstring' '--enable-mbregex' '--with-mcal' '--with-mcrypt' '--with-mhash' '--with-ming' '--with-mysql' '--with-ncurses' '--with-pdflib' '--with-readline' '--enable-shmop' '--enable-sysvsem' '--enable-sysvshm' '--enable-wddx' '--enable-versioning' '--with-xml' '--enable-ctype' phpinfo: http://www.planetcoding-server.net/phpinfo.php PatchesPull RequestsHistoryAllCommentsChangesGit/SVN commits
|
|||||||||||||||||||||||||||||||||||||
Copyright © 2001-2026 The PHP GroupAll rights reserved. |
Last updated: Thu Oct 08 04:00:01 2026 UTC |
this code: __________________________ ob_start(); show_source("files/".$version_info['version_id'].ifelse($file_info['extension'],".".$file_info['extension'])); $source = ob_get_contents(); ob_end_clean(); __________________________ throws this error: Warning: show_source() [function.show-source.html]: SAFE MODE Restriction in effect. The script whose uid is 641 is not allowed to access files/21.php owned by uid 30 in /home/www/web5/html/browse.php on line 240 this code (and any other file operations) works: __________________________ ob_start(); $fp=fopen("files/".$version_info['version_id'].ifelse($file_info['extension'],".".$file_info['extension']),'r'); $source = fread($fp,filesize("files/".$version_info['version_id'].ifelse($file_info['extension'],".".$file_info['extension']))); highlight_string($source); $source = ob_get_contents(); ob_end_clean(); __________________________